[Bug 295270] www/nginx: Update to 1.30.1 to fix security issues
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 13 May 2026 18:44:05 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295270
Bug ID: 295270
Summary: www/nginx: Update to 1.30.1 to fix security issues
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: joneum@FreeBSD.org
Reporter: chris@cretaforce.gr
Flags: maintainer-feedback?(joneum@FreeBSD.org)
Assignee: joneum@FreeBSD.org
nginx-1.30.1 stable and nginx-1.31.0 mainline versions have been released, with
fixes for HTTP/2 request injection vulnerability in the ngx_http_proxy_module
(CVE-2026-42926), buffer overflow vulnerability in the ngx_http_rewrite_module
(CVE-2026-42945), buffer overread vulnerabilities in the ngx_http_scgi_module
and ngx_http_uwsgi_module (CVE-2026-42946), buffer overread vulnerability in
the ngx_http_charset_module (CVE-2026-42934), address spoofing vulnerability in
HTTP/3 (CVE-2026-40460), and use-after-free vulnerability in OCSP requests to
resolver (CVE-2026-40701). Additionally, nginx-1.31.0 mainline version features
support for HTTP forward proxy.
--
You are receiving this mail because:
You are the assignee for the bug.